Remix.run Logo
gnabgib 14 hours ago

It's in the article.. they hijacked the DNS to send the users to an alt phishing website.. looked identical to the Entra (M365) flow.. but the victims were sending their data/secrets/TOTP to hackers on slightly different URLs.

Most people are so used to the login flow, they don't inspect the URLS if the page looks right. Some popups even obscure the URL (almost impossible to detect).